首页> 外文会议>International Conference on Information and Communications Security >Parameter Pollution Vulnerabilities Detection Study Based on Tree Edit Distance
【24h】

Parameter Pollution Vulnerabilities Detection Study Based on Tree Edit Distance

机译:基于树编辑距离的参数污染漏洞检测研究

获取原文

摘要

A new web attack pattern called HTTP Parameter Pollution has been presented in recent years. The harm and detection method about HPP has become a hot topic in the field of web application security. In the paper, we started with analyzing the HPP attack pattern, researched on the necessary conditions and the potential harm of attack, pointed that the determination of parameter precedence is a prerequisite for the implementation and testing of such attacks, and proposed determination method for parameter priority based on tree edit distance to provide the necessary support for HPP vulnerabilities detection. As well as, we developed different detection methods for the difference of parameters between URL and the page. Finally the detection system for HPP vulnerability was realized, and some vulnerabilities have been discovered in real world.
机译:近年来,已经提出了一种名为HTTP参数污染的新的Web攻击模式。关于HPP的危害和检测方法已成为Web应用程序安全领域的热门话题。在论文中,我们开始分析了对必要条件和攻击潜在危害的HPP攻击模式,指出了参数优先级的确定是实施和测试此类攻击的先决条件,以及参数的建议确定方法基于树编辑距离的优先级为HPP漏洞检测提供必要的支持。以及我们开发了用于URL和页面之间参数差异的不同检测方法。最后,实现了HPP漏洞的检测系统,在现实世界中发现了一些漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号